[ Applies to ] StorageGuard / HPE Alletra 9000, Alletra MP and Primera / Block & SAN Storage
This article lists the recommended baseline checks for HPE Alletra 9000, Alletra MP and Primera. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
HPE Alletra 9000, Alletra Storage MP and HPE Primera are enterprise block storage platforms for mission-critical workloads. They combine thin provisioning, data reduction and multi-site replication with a highly available, scalable architecture.
Why hardening HPE Alletra 9000, Alletra MP and Primera matters
These arrays store and serve sensitive data such as customer records, financial data and intellectual property. Enforcing encryption, strict access controls, secure management interfaces and audit logging protects that data and minimizes the risk of disruption to the applications that depend on it.
Recommended baseline checks
The baseline below contains 96 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-F6021T250V01 | Access control list status - Console security |
| SG-C0393T250V01 | Account lockout threshold |
| SG-C0449T250V01 | Approved DNS servers |
| SG-C0044T250V01 | Approved KMS server |
| SG-C0435T250V01 | Approved LDAP servers |
| SG-C0013T250V01 | Approved NTP servers |
| SG-C0406T250V01 | Approved SMTP server |
| SG-C0314T250V01 | Approved SMTP user |
| SG-C0348T250V01 | Approved SNMP trap hosts |
| SG-C0333T250V01 | Approved user roles |
| SG-C0430T250V01 | Autosupport status |
| SG-C0032T250V01 | Central authentication |
| SG-C0029T250V01 | Centralized log server |
| SG-C0233T250V01 | Centralized log server redundancy |
| SG-F2167T250V01 | Certificate for unified server |
| SG-C0415T250V01 | Certificate signature algorithm |
| SG-C0702T250V01 | Common Criteria mode enabled |
| SG-F8377T250V01 | Configured method for recovery account authentication |
| SG-C0065T250V01 | Data at-rest encryption |
| SG-C0073T250V01 | Data encryption strength |
| SG-F9008T250V01 | Default password - SSMC |
| SG-F4920T250V01 | Disable unencrypted ports |
| SG-C0243T250V01 | DNS server configuration |
| SG-C0060T250V01 | DNS server redundancy |
| SG-F3896T250V01 | Domain maximum virtual volume retention time |
| SG-C0245T250V01 | Domain name configuration |
| SG-C0177T250V01 | FIPS mode status |
| SG-F9119T250V01 | HPE OneView default password |
| SG-C0381T250V01 | HTTP service status |
| SG-C0209T250V01 | Idle session timeout |
| SG-C0038T250V01 | Kerberos status |
| SG-F4373T250V01 | Key Manager mutual authentication |
| SG-F1548T250V01 | Key Manager server certificate |
| SG-C0047T250V01 | KMIP status |
| SG-C0049T250V01 | KMS server configuration |
| SG-C0052T250V01 | KMS server redundancy |
| SG-F7150T250V01 | LDAP Binding mode |
| SG-F9153T250V01 | LDAP certificate |
| SG-F7615T250V01 | LDAP group mapping |
| SG-C0039T250V01 | LDAP server configuration |
| SG-F6336T250V01 | Local log size |
| SG-C0509T250V01 | Log forwarding |
| SG-C0427T250V01 | Login banner message |
| SG-C0426T250V01 | Login banner status |
| SG-C0701T250V01 | Master key status |
| SG-C0468T250V01 | Maximum concurrent sessions |
| SG-C0269T250V01 | Maximum number of repeated password characters |
| SG-C0270T250V01 | Minimum password digits |
| SG-C0264T250V01 | Minimum password length |
| SG-C0271T250V01 | Minimum password lowercase characters |
| SG-C0272T250V01 | Minimum password special characters |
| SG-C0273T250V01 | Minimum password uppercase characters |
| SG-C0239T250V01 | Multi-factor authentication |
| SG-C0194T250V01 | NFS browsable exports |
| SG-C0192T250V01 | NFS export allowed access list |
| SG-C0377T250V01 | NFS root squash status |
| SG-C0230T250V01 | Non-default local admin |
| SG-C0231T250V01 | Non-default local users |
| SG-C0171T250V01 | NTP server configuration |
| SG-C0432T250V01 | NTP server redundancy |
| SG-C0284T250V01 | Password history |
| SG-F8766T250V01 | ReadOnly snapshot |
| SG-F3731T250V01 | Remote copy status |
| SG-F1628T250V01 | Required LDAP group mapping |
| SG-C0014T250V01 | Required NTP servers |
| SG-F2870T250V01 | Secure proxy protocol |
| SG-F2245T250V01 | Service location protocol Status |
| SG-C0011T250V01 | SMTP authentication |
| SG-C0364T250V01 | SMTP security |
| SG-C0395T250V01 | SMTP server configuration |
| SG-C0058T250V01 | SNMP community default string |
| SG-C0155T250V01 | SNMP service disabled |
| SG-C0347T250V01 | SNMP trap host configuration |
| SG-C0123T250V01 | SNMP versions enabled |
| SG-F2213T250V01 | SNMPv3 authentication and privacy protocols |
| SG-C0258T250V01 | SSH cipher strength |
| SG-F3357T250V01 | SSMC Access List |
| SG-F9082T250V01 | SSMC Email notification |
| SG-F5389T250V01 | SSMC max user sessions |
| SG-F1611T250V01 | SSMC NTP |
| SG-F8542T250V01 | SSMC session timeout |
| SG-F8616T250V01 | SSMC SYSLOG |
| SG-F1133T250V01 | SSMC TLS |
| SG-F7269T250V01 | Storage default password |
| SG-C0229T250V01 | Support tunnel status |
| SG-F3423T250V01 | Syslog mutual authentication |
| SG-F4084T250V01 | Syslog Protocol |
| SG-C0019T250V01 | Target OS version |
| SG-C0385T250V01 | Telnet service status |
| SG-C0017T250V01 | Unauthenticated Syslog server |
| SG-F2795T250V01 | Unneeded protocols disabled |
| SG-C0213T250V01 | Use of secure LDAP |
| SG-F3108T250V01 | User session limits |
| SG-F6483T250V01 | Valid user for SNMP Manager |
| SG-F6597T250V01 | VASA TLS method |
| SG-F5274T250V01 | WORM changes require compliance officer approval |
Related components
A complete baseline also covers the components that manage, connect to or protect HPE Alletra 9000, Alletra MP and Primera. Review the configuration of:
- HPE Storage System Management Console (SSMC)
- HPE OneView
- External key managers
- Remote Copy peers
Run a checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.